This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Virtumonde Infection

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

While doing a Spybot scan, I noticed that virtumonde.sci and virtumonde.sdn took up over 300,000 of a total 593,000 items. How can I remove this? I have run Malwarebytes, Super antispyware and Combofix and its still there. This is on Windows Office XP. Thanks. Root Repeal log: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/07 18:31 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xA98C2000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8BAE000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA8BCB000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 017 Function Name: NtAllocateVirtualMemory Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf8298b30 #: 025 Function Name: NtClose Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e26b8 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e2574 #: 053 Function Name: NtCreateThread Status: Hooked by "" at address 0xf8d896c4 #: 063 Function Name: NtDeleteKey Status: Hooked by "" at address 0xf8d896d3 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e2a52 #: 068 Function Name: NtDuplicateObject Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e214c #: 098 Function Name: NtLoadKey Status: Hooked by "" at address 0xf8d896e2 #: 108 Function Name: NtMapViewOfSection Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf8298470 #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e264e #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e208c #: 128 Function Name: NtOpenThread Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e20f0 #: 137 Function Name: NtProtectVirtualMemory Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf8298c50 #: 177 Function Name: NtQueryValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e276e #: 193 Function Name: NtReplaceKey Status: Hooked by "" at address 0xf8d896ec #: 204 Function Name: NtRestoreKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e272e #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa98e28ae #: 249 Function Name: NtShutdownSystem Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf8298990 #: 257 Function Name: NtTerminateProcess Status: Hooked by "" at address 0xf8d896bf #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf8298d60 ==EOF== DDS.txt: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 18:25:22.67 on Mon 09/07/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.219 [GMT -6:00] AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7} AV: avast! antivirus 4.8.1351 [VPS 090907-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: Sygate Personal Firewall *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.wrh.noaa.gov/forecast/MapClick.php?site=tfx&smap=1&textField1=47.02611&textField2=-108.80389 uSearch Page = hxxp://www.google.com uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: StumbleUpon Launcher: {145b29f4-a56b-4b90-bbac-45784ebebbb7} - c:\program files\stumbleupon\StumbleUponIEBar.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\windows\system32\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: StumbleUpon Toolbar: {5093eb4c-3e93-40ab-9266-b607ba87bdc8} - c:\program files\stumbleupon\StumbleUponIEBar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [SmcService] c:\progra~1\sygate\spf\smc.exe -startgui mRun: [RTHDCPL] RTHDCPL.EXE mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\owner\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bbstar~1.lnk - c:\program files\brainbullet!\BBStartup.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\status~1.lnk - c:\program files\brother\brmfcmon\BrMfcWnd.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - {2151DA8C-C5B6-4B4F-86AB-BDA449BF8747} - c:\program files\evernote\evernote\enbar.dll Trusted Zone: microsoft.com\www.update DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} - hxxps://www2.gotomeeting.com/default/applets/g2mdlax.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab TCP: {094696E5-492F-41A3-BBB7-C1C2D614E956} = 216.228.34.51 206.74.254.2 Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll,c:\progra~1\google\google~1\GOEC62~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\pb61cq7v.default\ FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-1-27 28544] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-3 114768] R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-3-18 11608] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-3-18 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-3-18 185089] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-3 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-11-9 138680] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-3-18 55656] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S2 gupdate1c9945cb04356b8;Google Update Service (gupdate1c9945cb04356b8);c:\program files\google\update\GoogleUpdate.exe [2009-2-21 133104] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-11-9 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-11-9 352920] S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [2006-6-30 69692] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-8-9 29744] S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\stumbleupon\StumbleUponUpdateService.exe [2009-6-3 120168] S4 vsdatant;vsdatant; [x] =============== Created Last 30 ================ 2009-09-07 07:06 –d—– c:\windows\Downloaded Installations 2009-09-06 22:15 –d—– c:\windows\$regcmp$ 2009-09-06 21:45 –d—– c:\windows\system32\wbem\Repository 2009-09-06 21:43 –d—– c:\program files\The Internet Marketing Center 2009-09-06 21:43 –d—– c:\program files\Panda Security 2009-09-06 21:43 –d—– c:\program files\Uniblue 2009-09-06 21:43 –d—– c:\program files\Citrix 2009-09-06 18:28 –d—– c:\program files\SUPERAntiSpyware 2009-09-06 18:28 –d—– c:\docume~1\owner\applic~1\SUPERAntiSpyware.com 2009-09-06 17:34 –d—– C:\RECYCLER(2) 2009-09-06 13:55 –d—– C:\cmdcons 2009-08-12 22:18 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll 2009-08-12 22:05 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx ==================== Find3M ==================== 2009-08-05 09:29 55,656 a——- c:\windows\system32\drivers\avgntflt.sys 2009-08-05 03:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-07-19 09:56 5,623,216 a——- C:\Opera_964_en_Setup.exe 2009-07-17 13:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll 2009-07-13 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-13 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-05 10:14 2,908 a——- c:\docume~1\owner\applic~1\wklnhst.dat 2009-07-03 11:09 915,456 a——- c:\windows\system32\wininet.dll 2009-06-25 02:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 02:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 02:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 02:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 02:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 02:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-16 08:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 08:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-12 06:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 08:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 00:14 132,096 a——- c:\windows\system32\wkssvc.dll 2009-05-25 15:25 0 —shr– c:\windows\FFSSET.BIN 2007-11-07 19:14 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat 2008-07-17 10:42 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008071720080718\index.dat ============= FINISH: 18:27:53.70 =============== Attach.txt: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 11/7/2007 6:09:01 PM System Uptime: 9/7/2009 6:33:08 AM (12 hours ago) Motherboard: ELITEGROUP | | 945GCT-M3 Processor: Intel Celeron processor | Socket 775 | 1599/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 70 GiB total, 51.459 GiB free. D: is FIXED (NTFS) - 4 GiB total, 1.417 GiB free. E: is CDROM () F: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4D36E967-E325-11CE-BFC1-08002BE10318} Description: Disk drive Device ID: IDE\DISKMAXTOR_6E020L0__________________________NAR61590\3145374252564546202020202020202020202020 Manufacturer: (Standard disk drives) Name: Maxtor 6E020L0 PNP Device ID: IDE\DISKMAXTOR_6E020L0__________________________NAR61590\3145374252564546202020202020202020202020 Service: disk ==== System Restore Points =================== RP577: 6/10/2009 10:03:35 AM - Software Distribution Service 3.0 RP578: 6/10/2009 12:27:09 PM - Software Distribution Service 3.0 RP579: 6/10/2009 3:47:11 PM - Software Distribution Service 3.0 RP580: 6/11/2009 11:18:15 AM - Software Distribution Service 3.0 RP581: 6/11/2009 1:11:39 PM - Software Distribution Service 3.0 RP582: 6/13/2009 8:24:08 PM - System Checkpoint RP583: 6/15/2009 12:04:19 PM - Software Distribution Service 3.0 RP584: 6/16/2009 3:24:08 PM - System Checkpoint RP585: 6/18/2009 9:54:05 AM - Software Distribution Service 3.0 RP586: 6/19/2009 10:57:43 AM - System Checkpoint RP587: 6/20/2009 12:42:50 PM - System Checkpoint RP588: 6/21/2009 10:29:18 AM - Installed Java™ 6 Update 14 RP589: 6/22/2009 1:31:36 PM - System Checkpoint RP590: 6/22/2009 10:48:14 PM - Software Distribution Service 3.0 RP591: 6/24/2009 10:56:26 AM - System Checkpoint RP592: 6/25/2009 11:47:07 AM - System Checkpoint RP593: 6/28/2009 6:47:37 PM - Software Distribution Service 3.0 RP594: 6/29/2009 7:05:05 PM - System Checkpoint RP595: 6/30/2009 7:10:29 PM - Software Distribution Service 3.0 RP596: 7/1/2009 7:47:41 PM - System Checkpoint RP597: 7/3/2009 8:37:01 AM - System Checkpoint RP598: 7/4/2009 3:37:33 PM - System Checkpoint RP599: 7/4/2009 7:04:24 PM - Software Distribution Service 3.0 RP600: 7/5/2009 8:05:54 PM - System Checkpoint RP601: 7/6/2009 7:26:33 PM - Software Distribution Service 3.0 RP602: 7/8/2009 11:03:03 AM - System Checkpoint RP603: 7/10/2009 9:19:23 AM - System Checkpoint RP604: 7/11/2009 9:30:26 AM - Software Distribution Service 3.0 RP605: 7/12/2009 12:14:23 PM - System Checkpoint RP606: 7/13/2009 5:55:50 PM - System Checkpoint RP607: 7/14/2009 6:55:37 PM - System Checkpoint RP608: 7/15/2009 11:52:55 AM - Installed QuickTime RP609: 7/15/2009 2:18:25 PM - Software Distribution Service 3.0 RP610: 7/16/2009 11:55:24 AM - Removed Lexmark Photo Center RP611: 7/17/2009 1:27:51 PM - System Checkpoint RP612: 7/17/2009 2:52:59 PM - Removed Java™ SE Runtime Environment 6 Update 1 RP613: 7/18/2009 9:04:20 AM - Software Distribution Service 3.0 RP614: 7/19/2009 9:57:17 AM - Installed Opera 9.64 RP615: 7/19/2009 5:53:14 PM - Removed Opera 9.64 RP616: 7/20/2009 5:56:48 PM - System Checkpoint RP617: 7/21/2009 11:06:13 AM - Software Distribution Service 3.0 RP618: 7/22/2009 11:46:38 AM - System Checkpoint RP619: 7/23/2009 1:44:50 PM - System Checkpoint RP620: 7/24/2009 12:51:39 PM - Software Distribution Service 3.0 RP621: 7/25/2009 2:29:54 PM - System Checkpoint RP622: 7/26/2009 4:47:44 PM - System Checkpoint RP623: 7/27/2009 7:37:22 PM - System Checkpoint RP624: 7/28/2009 12:53:19 PM - Software Distribution Service 3.0 RP625: 7/29/2009 1:30:15 PM - System Checkpoint RP626: 7/30/2009 2:35:49 PM - System Checkpoint RP627: 8/1/2009 10:43:25 AM - System Checkpoint RP628: 8/1/2009 12:35:16 PM - Software Distribution Service 3.0 RP629: 8/2/2009 12:59:43 PM - System Checkpoint RP630: 8/3/2009 5:11:09 PM - System Checkpoint RP631: 8/4/2009 10:59:32 PM - System Checkpoint RP632: 8/5/2009 7:06:43 AM - Software Distribution Service 3.0 RP633: 8/6/2009 7:53:17 AM - System Checkpoint RP634: 8/7/2009 10:38:57 AM - System Checkpoint RP635: 8/8/2009 7:00:48 AM - Software Distribution Service 3.0 RP636: 8/9/2009 12:53:34 PM - System Checkpoint RP637: 8/10/2009 12:17:06 PM - Software Distribution Service 3.0 RP638: 8/12/2009 10:49:41 AM - System Checkpoint RP639: 8/12/2009 10:54:39 PM - Software Distribution Service 3.0 RP640: 8/14/2009 11:59:56 AM - System Checkpoint RP641: 8/15/2009 3:29:41 PM - System Checkpoint RP642: 8/16/2009 3:30:44 PM - System Checkpoint RP643: 8/18/2009 11:32:44 AM - System Checkpoint RP644: 8/19/2009 10:07:52 PM - Software Distribution Service 3.0 RP645: 8/20/2009 10:52:49 PM - System Checkpoint RP646: 8/22/2009 12:55:03 PM - System Checkpoint RP647: 8/23/2009 3:14:41 PM - System Checkpoint RP648: 8/24/2009 7:11:43 AM - Software Distribution Service 3.0 RP649: 8/25/2009 6:48:21 AM - Software Distribution Service 3.0 RP650: 8/26/2009 10:23:36 AM - System Checkpoint RP651: 8/27/2009 8:26:13 AM - Software Distribution Service 3.0 RP652: 8/28/2009 10:27:43 AM - System Checkpoint RP653: 8/29/2009 11:53:27 AM - Software Distribution Service 3.0 RP654: 8/30/2009 2:04:24 PM - System Checkpoint RP655: 8/31/2009 4:41:32 PM - System Checkpoint RP656: 9/1/2009 7:28:11 PM - System Checkpoint RP657: 9/2/2009 9:40:21 AM - Installed Image Resizer Powertoy for Windows XP RP658: 9/3/2009 6:58:07 AM - Software Distribution Service 3.0 RP659: 9/4/2009 11:12:43 AM - System Checkpoint RP660: 9/5/2009 6:07:13 AM - Software Distribution Service 3.0 RP661: 9/6/2009 3:04:54 PM - System Checkpoint RP662: 9/6/2009 6:28:02 PM - Installed SUPERAntiSpyware Free Edition RP663: 9/6/2009 9:07:58 PM - Restore Operation RP664: 9/6/2009 9:42:31 PM - Restore Operation RP665: 9/7/2009 7:06:46 AM - Installed Image Resizer Powertoy for Windows XP RP666: 9/7/2009 7:20:07 AM - Installed Magnifier Powertoy for Windows XP ==== Installed Programs ====================== Ad-Aware Adobe Dynamic Content Server Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.6 Adobe SVG Viewer 3.0 Apple Software Update AusLogics Disk Defrag avast! Antivirus Avira AntiVir Personal - Free Antivirus BookScan&Whiteboard Suite BrainBullet! 2.0 Brother MFL-Pro Suite MFC-290C Browser Address Error Redirector CCleaner (remove only) Compatibility Pack for the 2007 Office system ConvertHelper 2.2 Critical Update for Windows Media Player 11 (KB959772) DVD Suite ERUNT 1.1j EverNote (Trial) FaceFilter Studio Brother Edition FileZilla Client [removed] Free Registry Defrag Google Desktop Google Earth Google Update Helper High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Image Resizer Powertoy for Windows XP Intel® Graphics Media Accelerator Driver InterActual Player Java™ 6 Update 14 Magnifier Powertoy for Windows XP Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Basic Edition 2003 Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works Microsoft WSE 2.0 SP3 Runtime Mozilla Firefox (3.5.2) MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) Outlook Express Backup V6.5 PageBreeze Free HTML Editor PaperPort Image Printer Power2Go 5.0 PowerDVD QuickTime Realtek High Definition Audio Driver Recovery Software Suite eMachines ScanSoft PaperPort 11 Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459)
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

1) Two AntiVirus Programs
Running two antivirus programs at once can slow a system down immensely and they can conflict.
Please go to Add/Remove programs and uninstall either Avast or Avira.

2) Combofix
Post your combofix log from your previous run, it should be located at C:\Combofix.txt.

3) What You Will Need To Post:
  • Confirmation that you removed one AV program
  • Old Combofix log
Raktor,
Thanks for your help.
I keep AvComboFix 09-09-06.02 - Owner 09/06/2009 13:56.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.251 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: avast! antivirus 4.8.1351 [VPS 090906-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Sygate Personal Firewall *enabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-1558776043-1237168866-2071810009-1003
c:\recycler\S-1-5-21-1729807143-1683264735-2586628803-1003
c:\recycler\S-1-5-21-360915446-4182279527-3184067265-1003
c:\recycler\S-1-5-21-3695411786-1413094918-240616462-1003
c:\windows\Installer\164b95.msp
c:\windows\Installer\c4440a.msi
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-08-06 to 2009-09-06 )))))))))))))))))))))))))))))))
.

2009-09-02 15:39 . 2009-09-02 15:39 ——– d—–w- c:\windows\Downloaded Installations
2009-08-13 04:18 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-09 18:24 . 2009-08-09 18:26 ——– d—–w- c:\windows\$regcmp$

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-06 19:39 . 2008-07-30 15:44 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-06 18:38 . 2009-01-20 16:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-06 18:21 . 2007-11-08 05:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-06 05:50 . 2009-07-23 20:26 ——– d—–w- c:\documents and settings\Owner\Application Data\vlc
2009-09-02 15:29 . 2009-05-25 20:05 ——– d—–w- c:\documents and settings\Owner\Application Data\Reallusion
2009-08-17 16:10 . 2007-11-09 06:45 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2007-11-09 06:46 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2007-11-09 06:46 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-04-04 00:26 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-04 00:26 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2007-11-09 06:46 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2007-11-09 06:46 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2007-11-09 06:46 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2007-11-09 06:46 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-16 20:02 . 2009-07-24 03:37 ——– d—–w- c:\program files\ZillaTube
2009-08-16 20:01 . 2009-07-21 01:12 ——– d—–w- c:\program files\Citrix
2009-08-16 20:00 . 2007-08-10 02:08 ——– d—–w- c:\program files\BigFix
2009-08-16 20:00 . 2007-08-10 01:55 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-05 15:53 . 2009-08-05 15:53 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-08-05 15:29 . 2009-03-18 17:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-05 09:01 . 2006-05-07 01:24 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 19:36 . 2009-01-20 16:18 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 19:36 . 2009-01-20 16:18 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-02 14:32 . 2009-01-23 01:44 ——– d—–w- c:\program files\Microsoft Silverlight
2009-08-01 20:01 . 2007-11-08 05:52 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-31 02:19 . 2007-11-09 16:32 ——– d—–w- c:\documents and settings\Owner\Application Data\StumbleUpon
2009-07-29 18:08 . 2009-07-29 17:41 ——– d—–w- c:\documents and settings\Owner\Application Data\FileZilla
2009-07-29 17:41 . 2009-07-29 17:41 ——– d—–w- c:\program files\FileZilla FTP Client
2009-07-29 12:44 . 2009-07-15 02:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Kodak
2009-07-29 12:44 . 2009-07-15 02:31 ——– d—–w- c:\program files\Kodak
2009-07-28 00:48 . 2009-07-28 00:48 ——– d—–w- c:\documents and settings\Owner\Application Data\PC-FAX TX
2009-07-27 16:15 . 2009-07-27 16:14 ——– d—–w- c:\program files\PageBreeze
2009-07-24 17:14 . 2009-07-23 18:49 ——– d—–w- c:\program files\ConvertHelper
2009-07-23 20:25 . 2009-07-23 20:25 ——– d—–w- c:\program files\VideoLAN
2009-07-20 17:03 . 2009-01-28 01:46 ——– d—–w- c:\program files\SpywareBlaster
2009-07-20 05:04 . 2009-02-11 06:44 126360 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-19 23:53 . 2009-07-19 15:57 ——– d—–w- c:\program files\Opera
2009-07-19 19:24 . 2009-02-10 23:47 ——– d—–w- c:\documents and settings\Owner\Application Data\uniblue
2009-07-19 19:24 . 2009-02-10 23:46 ——– d—–w- c:\program files\Uniblue
2009-07-19 18:57 . 2009-07-19 18:57 ——– d—–w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-07-19 15:56 . 2009-07-19 15:56 5623216 —-a-w- C:\Opera_964_en_Setup.exe
2009-07-17 19:01 . 2006-05-07 01:24 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-15 17:55 . 2009-07-15 02:34 ——– d—–w- c:\program files\QuickTime
2009-07-15 17:54 . 2009-07-15 17:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-15 17:50 . 2009-07-15 17:50 ——– d—–w- c:\program files\Apple Software Update
2009-07-15 17:50 . 2009-07-15 17:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-07-15 02:41 . 2009-07-15 02:41 ——– d—–w- c:\documents and settings\Owner\Application Data\Skinux
2009-07-14 05:43 . 2006-05-07 01:24 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-13 23:40 . 2007-11-11 18:31 ——– d—–w- c:\documents and settings\Owner\Application Data\U3
2009-07-05 16:14 . 2008-03-05 07:28 2908 —-a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-07-03 17:09 . 2006-05-07 01:24 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2006-05-07 01:24 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2006-05-07 01:24 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2006-05-07 01:24 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2006-05-07 01:24 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2006-05-07 01:24 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2006-05-07 01:24 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2006-05-07 01:24 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2006-05-07 01:24 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2006-05-07 01:24 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2006-05-07 01:24 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 15:19 . 2006-05-07 01:35 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2006-05-07 01:24 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2006-05-07 01:24 132096 —-a-w- c:\windows\system32\wkssvc.dll
2008-09-26 04:19 . 2008-09-26 04:20 122880 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-05-25 21:25 . 2009-05-25 21:25 0 –sh–r- c:\windows\FFSSET.BIN
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-16 2577632]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-06 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-09-22 14854144]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BBStartup.lnk.lnk - c:\program files\BrainBullet!\BBStartup.exe [2009-1-10 403968]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2009-5-25 1089536]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Power2GoExpress"=NA
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe"
"BigFix"=c:\program files\Bigfix\bigfix.exe /atstartup
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"Recguard"=%WINDIR%\SMINST\RECGUARD.EXE
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\DC_Web_Server\\php\\apache\\Apache.exe"=
"c:\\DC_Web_Server\\jsp\\java\\bin\\java.exe"=
"c:\\Program Files\\Adobe\\GoLive 6.0_ENG\\GoLive.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [1/27/2009 9:27 AM 28544]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/3/2008 6:26 PM 114768]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [3/18/2009 11:33 AM 108289]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/3/2008 6:26 PM 20560]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S2 gupdate1c9945cb04356b8;Google Update Service (gupdate1c9945cb04356b8);c:\program files\Google\Update\GoogleUpdate.exe [2/21/2009 1:43 PM 133104]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [6/30/2006 11:44 PM 69692]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [8/9/2007 8:03 PM 29744]
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\StumbleUpon\StumbleUponUpdateService.exe [6/3/2009 2:52 PM 120168]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-21 19:43]

2009-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-21 19:43]

2009-09-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]

2009-09-06 c:\windows\Tasks\User_Feed_Synchronization-{55079776-2A7F-4729-B367-1676E5960049}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 10:31]
.
- - - - ORPHANS REMOVED - - - -

Toolbar-SITEguard - (no file)
Toolbar-Locked - (no file)
HKLM-Run-NSS - c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.3.0.44\InstStub.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.wrh.noaa.gov/forecast/MapClick.php?site=tfx&smap=1&textField1=47.02611&textField2=-108.80389
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
Trusted Zone: microsoft.com\www.update
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\pb61cq7v.default\
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-06 14:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)ast inactive and every couple weeks in deactivate Avira and run a scan with Avast. Do I still need to remove one, and if so, which one do you think is better?
Here is my Combofix:
Keep either, it's 100% up to you - since you use Avira least I'd just get rid of that. It doesn't appear from any of the logs that you've posted that you are infected. Is there anything that is making you still believe you're infected?
On the last Spybot scan, Virtumonde had well over half of the 594,000 files that were scanned. Won't this just get bigger, and slow my computer down more all the time?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI